#Chrome extensions can steal plaintext passwords from websites
source: bleepingcomputer.com/news/secu…
The researchers explain that the #problem concerns the systemic practice of giving #browser extensions unrestricted #access to the #DOM tree of sites they load on, which allows accessing potentially sensitive elements such as user input fields.
#extension #addon #warning #password #security #fail #news
Chrome extensions can steal plaintext passwords from websites
A team of researchers from the University of Wisconsin-Madison has uploaded to the Chrome Web Store a proof-of-concept extension that can steal plaintext passwords from a website's source code.Bill Toulas (BleepingComputer)
Zoltan Toth likes this.
reshared this